mirror of
https://github.com/j3ssie/osmedeus.git
synced 2026-09-29 04:54:57 +02:00
Complete rewrite and re-architecture Osmedeus Engine in v5
This commit is contained in:
@@ -0,0 +1,35 @@
|
||||
# Basic Reconnaissance Flow
|
||||
# Orchestrates subdomain enumeration, port scanning, and HTTP probing
|
||||
|
||||
name: basic-recon
|
||||
kind: flow
|
||||
description: Basic reconnaissance flow - subdomain enum, port scan, http probe
|
||||
tags: test, recon, flow
|
||||
|
||||
|
||||
params:
|
||||
- name: threads
|
||||
value: "10"
|
||||
- name: timeout
|
||||
value: "3600"
|
||||
|
||||
modules:
|
||||
# Module 1: Subdomain Enumeration
|
||||
- name: subdomain-enumeration
|
||||
path: modules/subdomain-enum.yaml
|
||||
params:
|
||||
threads: "{{threads}}"
|
||||
condition: "true"
|
||||
exports:
|
||||
enum_subdomains: "{{final_subdomains}}"
|
||||
|
||||
# Module 2: HTTP Probing (depends on subdomain enumeration)
|
||||
- name: http-probing
|
||||
path: modules/http-probe.yaml
|
||||
depends_on:
|
||||
- subdomain-enumeration
|
||||
params:
|
||||
threads: "{{threads}}"
|
||||
condition: "fileLength('{{enum_subdomains}}') > 0"
|
||||
exports:
|
||||
http_results: "{{http_hosts}}"
|
||||
@@ -0,0 +1,81 @@
|
||||
# Full Comprehensive Scan Flow
|
||||
# Orchestrates all 5 modules in a complete security assessment pipeline
|
||||
|
||||
name: full-scan
|
||||
kind: flow
|
||||
description: Full comprehensive scan - all modules orchestrated
|
||||
tags: test, full, flow
|
||||
|
||||
|
||||
params:
|
||||
- name: threads
|
||||
value: "10"
|
||||
- name: severity
|
||||
value: "critical,high,medium,low"
|
||||
- name: timeout
|
||||
value: "14400"
|
||||
|
||||
modules:
|
||||
# Stage 1: Subdomain Enumeration
|
||||
- name: subdomain-enumeration
|
||||
path: modules/subdomain-enum.yaml
|
||||
params:
|
||||
threads: "{{threads}}"
|
||||
condition: "true"
|
||||
exports:
|
||||
all_subdomains: "{{final_subdomains}}"
|
||||
|
||||
# Stage 2: Port Scanning (depends on subdomain enumeration)
|
||||
- name: port-scanning
|
||||
path: modules/port-scan.yaml
|
||||
depends_on:
|
||||
- subdomain-enumeration
|
||||
params:
|
||||
threads: "{{threads}}"
|
||||
ports: "80,443,8080,8443,22,21,25,53,3306,5432"
|
||||
condition: "fileLength('{{all_subdomains}}') > 0"
|
||||
exports:
|
||||
open_ports: "{{all_ports}}"
|
||||
|
||||
# Stage 3: HTTP Probing (depends on port scanning)
|
||||
- name: http-probing
|
||||
path: modules/http-probe.yaml
|
||||
depends_on:
|
||||
- port-scanning
|
||||
params:
|
||||
threads: "{{threads}}"
|
||||
condition: "fileLength('{{open_ports}}') > 0"
|
||||
exports:
|
||||
http_hosts: "{{http_hosts}}"
|
||||
|
||||
# Stage 4: Screenshot Capture (depends on HTTP probing)
|
||||
- name: screenshot-capture
|
||||
path: modules/screenshot.yaml
|
||||
depends_on:
|
||||
- http-probing
|
||||
params:
|
||||
threads: "5"
|
||||
timeout: "30"
|
||||
condition: "fileLength('{{http_hosts}}') > 0"
|
||||
|
||||
# Stage 5: Vulnerability Scanning (depends on HTTP probing)
|
||||
# Can run in parallel with screenshot capture since they both depend on http-probing
|
||||
- name: vulnerability-scanning
|
||||
path: modules/vuln-scan.yaml
|
||||
depends_on:
|
||||
- http-probing
|
||||
params:
|
||||
threads: "{{threads}}"
|
||||
severity: "{{severity}}"
|
||||
timeout: "3600"
|
||||
condition: "fileLength('{{http_hosts}}') > 0"
|
||||
on_success:
|
||||
- type: function
|
||||
script: |
|
||||
log_info("=== Full Scan Completed Successfully ===");
|
||||
log_info("Target: {{Target}}");
|
||||
log_info("All stages executed.");
|
||||
on_error:
|
||||
- type: function
|
||||
script: |
|
||||
log_error("Vulnerability scanning stage failed");
|
||||
@@ -0,0 +1,44 @@
|
||||
# Vulnerability Assessment Flow
|
||||
# Orchestrates HTTP probing followed by vulnerability scanning
|
||||
|
||||
name: vuln-assessment
|
||||
kind: flow
|
||||
description: Vulnerability assessment flow - http probe, then vuln scan
|
||||
tags: test, vuln, flow
|
||||
|
||||
params:
|
||||
- name: threads
|
||||
value: "10"
|
||||
- name: severity
|
||||
value: "critical,high,medium"
|
||||
- name: timeout
|
||||
value: "7200"
|
||||
|
||||
modules:
|
||||
# Module 1: HTTP Probing to find live hosts
|
||||
- name: http-probing
|
||||
path: modules/http-probe.yaml
|
||||
params:
|
||||
threads: "{{threads}}"
|
||||
condition: "true"
|
||||
exports:
|
||||
live_hosts: "{{http_hosts}}"
|
||||
|
||||
# Module 2: Vulnerability Scanning (depends on HTTP probing)
|
||||
- name: vulnerability-scanning
|
||||
path: modules/vuln-scan.yaml
|
||||
depends_on:
|
||||
- http-probing
|
||||
params:
|
||||
threads: "{{threads}}"
|
||||
severity: "{{severity}}"
|
||||
timeout: "{{timeout}}"
|
||||
condition: "fileLength('{{live_hosts}}') > 0"
|
||||
on_success:
|
||||
- type: function
|
||||
script: |
|
||||
log_info("Vulnerability assessment completed successfully");
|
||||
on_error:
|
||||
- type: function
|
||||
script: |
|
||||
log_error("Vulnerability scanning failed");
|
||||
Reference in New Issue
Block a user